logo

Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed

ID: d1c3b63d-b236-510a-8bed-79891b671742

STIX ID: report--d1c3b63d-b236-510a-8bed-79891b671742

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-12-28

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

A critical MongoDB vulnerability named MongoBleed (CVE-2025-14847) allows unauthenticated attackers to trigger zlib-based decompression memory leaks and exfiltrate in-memory secrets (credentials, API/cloud keys, tokens, PII). A public PoC is available and active exploitation has been observed; Censys found ~87,000 potentially vulnerable instances and cloud telemetry shows widespread exposure. MongoDB released patches and recommends updating (or disabling zlib) while detection tools and log parsers have been published to hunt for exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.